Re: [PATCH] KEYS: asym_tpm: Switch to get_random_bytes()

2019-10-07 Thread Ken Goldman
The TPM library specification states that the TPM must comply with NIST SP800-90 A. https://trustedcomputinggroup.org/membership/certification/tpm-certified-products/ shows that the TPMs get third party certification, Common Criteria EAL 4+. While it's theoretically possible that an attacker c

Re: [RFC 0/2] add integrity and security to TPM2 transactions

2018-04-08 Thread Ken Goldman
On 3/5/2018 9:04 AM, Jason Gunthorpe wrote: On Fri, Mar 02, 2018 at 10:04:54PM -0800, James Bottomley wrote: By now, everybody knows we have a problem with the TPM2_RS_PW easy button on TPM2 in that transactions on the TPM bus can be intercepted and altered.  The way to fix this is to use real s